MAL-2026-12206

    Dashboard / Malicious Package / MAL-2026-12206

    MAL-2026-12206

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in simple-date-formatter-util-8 (npm)

    Details: Source: amazon-inspector (28db20339e88b1f37da250a38c838eae62b32419a4c36e806b7c6367671f064c) package.json declares a postinstall lifecycle script that runs curl against the hardcoded bare-IP endpoint http://124.221.154.135/pre, passing the installer's hostname and username as query parameters ($(hostname), $(whoami)). The package presents itself as a trivial date-formatting utility, a purpose that has no need for network I/O at install time. The behavior fires automatically on npm install and leaks installer host identity to a non-first-party attacker-controlled endpoint.

    Affected packages

    Package

    Name: simple-date-formatter-util-8

    Purl: pkg:npm/simple-date-formatter-util-8

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0